Emulsify CLI does not publish a long-term support matrix. When reporting a
vulnerability, identify every affected @emulsify/cli version you have tested
and, when possible, confirm whether the latest published version is affected.
Maintainers will assess fixes and any backports based on the report's impact
and compatibility requirements.
Do not open a public GitHub issue for a suspected vulnerability or include exploit details in a public discussion.
TODO(contact): Replace this placeholder with the private security reporting email address or URL.
Include the following information when it is safe to do so:
- the affected Emulsify CLI version;
- the Node.js version and operating system;
- the expected impact and who may be affected;
- reproduction steps or a minimal proof of concept;
- any known mitigations; and
- whether the report or its details have been shared elsewhere.
The maintainers will use the private reporting channel to coordinate validation, remediation, and disclosure. Ordinary bugs and feature requests belong in the repository's public issue templates.